use std::fs;
use std::path::{Path, PathBuf};
fn repo_root() -> PathBuf {
PathBuf::from(env!("CARGO_MANIFEST_DIR"))
}
fn workspace_sources() -> Vec<PathBuf> {
let root = repo_root();
let mut files = Vec::new();
rust_sources(&root.join("src"), &mut files);
for krate in fs::read_dir(root.join("crates"))
.expect("crates/ is readable")
.flatten()
{
let src = krate.path().join("src");
if src.is_dir() {
rust_sources(&src, &mut files);
}
}
files
}
fn rust_sources(dir: &Path, out: &mut Vec<PathBuf>) {
for entry in fs::read_dir(dir).expect("src/ is readable").flatten() {
let path = entry.path();
if path.is_dir() {
rust_sources(&path, out);
} else if path.extension().is_some_and(|ext| ext == "rs") {
out.push(path);
}
}
}
fn is_test_file(relative: &str) -> bool {
relative.contains("/tests/")
|| relative.ends_with("/tests.rs")
|| relative.ends_with("/testutil.rs")
}
fn production_part(text: &str) -> &str {
let mut offset = 0;
let mut lines = text.split_inclusive('\n').peekable();
while let Some(line) = lines.next() {
if line.trim() == "#[cfg(test)]" && lines.peek().is_some_and(|next| is_mod_decl(next)) {
return &text[..offset];
}
offset += line.len();
}
text
}
fn is_mod_decl(line: &str) -> bool {
let line = line.trim_start();
let rest = line
.strip_prefix("pub(crate) ")
.or_else(|| line.strip_prefix("pub(super) "))
.or_else(|| line.strip_prefix("pub "))
.unwrap_or(line);
rest.starts_with("mod ")
}
#[test]
fn production_code_never_reaches_the_raw_pool() {
let root = repo_root();
let files = workspace_sources();
let mut offenders = Vec::new();
for path in files {
let relative = path
.strip_prefix(&root)
.unwrap()
.to_string_lossy()
.replace('\\', "/");
if relative.starts_with("crates/store/src/") || is_test_file(&relative) {
continue;
}
let text = fs::read_to_string(&path).unwrap();
for (index, line) in production_part(&text).lines().enumerate() {
if line.contains("raw_pool(") {
offenders.push(format!("{relative}:{}: {}", index + 1, line.trim()));
}
}
}
assert!(
offenders.is_empty(),
"`Database::raw_pool` is for test fixtures only; production code goes \
through a table module in `crates/store/`, `Database::transaction` or \
`Database::pool_stats`:\n{}",
offenders.join("\n"),
);
}
#[test]
fn the_cli_never_builds_a_signer() {
let root = repo_root();
let mut files = Vec::new();
rust_sources(&root.join("src/cli"), &mut files);
let mut offenders = Vec::new();
for path in files {
let relative = path
.strip_prefix(&root)
.unwrap()
.to_string_lossy()
.replace('\\', "/");
if is_test_file(&relative) {
continue;
}
let text = fs::read_to_string(&path).unwrap();
for (index, line) in production_part(&text).lines().enumerate() {
if line.contains("signer::from_config(") || line.contains("build_backends(") {
offenders.push(format!("{relative}:{}: {}", index + 1, line.trim()));
}
}
}
assert!(
offenders.is_empty(),
"the CLI records what it asks of a signer in the database and the job \
queue, and never builds a backend:\n{}",
offenders.join("\n"),
);
}
#[test]
fn the_request_path_never_holds_a_signer() {
const REQUEST_PATH: &[&str] = &[
"crates/protocol/src/handlers",
"crates/protocol/src/extractors",
"crates/protocol/src/middlewares",
"crates/admin/src/webadmin",
"crates/admin/src/admin",
"crates/protocol/src/router.rs",
"crates/protocol/src/profile.rs",
];
const FORBIDDEN: &[&str] = &[
"SignerBackend",
"Revoker::Backend(",
"signer::from_config(",
"build_backends(",
];
let root = repo_root();
let mut files = Vec::new();
for entry in REQUEST_PATH {
let path = root.join(entry);
if path.is_dir() {
rust_sources(&path, &mut files);
} else {
files.push(path);
}
}
assert!(
files.len() > REQUEST_PATH.len(),
"the walk found the sources"
);
let mut offenders = Vec::new();
for path in files {
let relative = path
.strip_prefix(&root)
.unwrap()
.to_string_lossy()
.replace('\\', "/");
if is_test_file(&relative) {
continue;
}
let text = fs::read_to_string(&path).unwrap();
for (index, line) in production_part(&text).lines().enumerate() {
let code = line.split("//").next().unwrap_or_default();
if FORBIDDEN.iter().any(|name| code.contains(name)) {
offenders.push(format!("{relative}:{}: {}", index + 1, line.trim()));
}
}
}
assert!(
offenders.is_empty(),
"a request is served from the signer's read side and queues what needs \
the key; it never holds a backend:\n{}",
offenders.join("\n"),
);
}
#[test]
fn only_the_schema_owners_apply_migrations() {
let root = repo_root();
let sources = workspace_sources();
const OWNERS: &[&str] = &[
"src/cli/mod.rs",
"crates/server/src/lib.rs",
"crates/store/src/db.rs",
];
let mut offenders = Vec::new();
for path in sources {
let relative = path
.strip_prefix(&root)
.unwrap_or(&path)
.to_string_lossy()
.replace('\\', "/");
if is_test_file(&relative) || OWNERS.contains(&relative.as_str()) {
continue;
}
let text = std::fs::read_to_string(&path).expect("a source file must be readable");
for (number, line) in production_part(&text).lines().enumerate() {
let code = line.trim_start();
if code.starts_with("//") {
continue;
}
if code.contains(".migrate()") || code.contains("connect_and_migrate(") {
offenders.push(format!("{relative}:{}: {}", number + 1, code));
}
}
}
assert!(
offenders.is_empty(),
"applying the schema belongs to `acme-proxy migrate`/`init` and to the `worker` role's \
startup gate; everything else checks `pending_migrations` and refuses by name:\n{}",
offenders.join("\n")
);
}
const CRATE_DEPS: &[(&str, &[&str])] = &[
("acme-proxy-core", &[]),
("acme-proxy-store", &["acme-proxy-core"]),
("acme-proxy-net", &["acme-proxy-core"]),
("acme-proxy-policy", &["acme-proxy-core", "acme-proxy-net"]),
(
"acme-proxy-jobs",
&["acme-proxy-core", "acme-proxy-net", "acme-proxy-store"],
),
(
"acme-proxy-signer",
&[
"acme-proxy-core",
"acme-proxy-jobs",
"acme-proxy-net",
"acme-proxy-store",
],
),
(
"acme-proxy-protocol",
&[
"acme-proxy-core",
"acme-proxy-jobs",
"acme-proxy-net",
"acme-proxy-policy",
"acme-proxy-signer",
"acme-proxy-store",
],
),
(
"acme-proxy-admin",
&[
"acme-proxy-core",
"acme-proxy-jobs",
"acme-proxy-policy",
"acme-proxy-protocol",
"acme-proxy-signer",
"acme-proxy-store",
],
),
(
"acme-proxy-server",
&[
"acme-proxy-admin",
"acme-proxy-core",
"acme-proxy-jobs",
"acme-proxy-net",
"acme-proxy-policy",
"acme-proxy-protocol",
"acme-proxy-signer",
"acme-proxy-store",
],
),
];
fn internal_deps(manifest: &str, table: &str) -> Vec<String> {
let header = format!("[{table}]");
let Some(start) = manifest.lines().position(|line| line.trim() == header) else {
return Vec::new();
};
let mut deps: Vec<String> = manifest
.lines()
.skip(start + 1)
.take_while(|line| !line.trim_start().starts_with('['))
.filter_map(|line| {
let name = line.split(['=', '.']).next()?.trim();
name.starts_with("acme-proxy-").then(|| name.to_string())
})
.collect();
deps.sort();
deps
}
#[test]
fn crate_dependencies_follow_the_layers() {
let root = repo_root();
let mut seen = Vec::new();
for entry in fs::read_dir(root.join("crates")).unwrap().flatten() {
if !entry.path().join("Cargo.toml").is_file() {
continue;
}
let manifest = fs::read_to_string(entry.path().join("Cargo.toml")).unwrap();
let name = manifest
.lines()
.find_map(|line| line.strip_prefix("name = "))
.map(|name| name.trim_matches('"').to_string())
.unwrap();
let allowed = CRATE_DEPS
.iter()
.find(|(krate, _)| *krate == name)
.unwrap_or_else(|| panic!("{name} is not in CRATE_DEPS"))
.1;
let mut expected: Vec<String> = allowed.iter().map(|dep| (*dep).to_string()).collect();
expected.sort();
assert_eq!(
internal_deps(&manifest, "dependencies"),
expected,
"{name}'s [dependencies] must name exactly the crates CRATE_DEPS allows it"
);
seen.push(name);
}
assert_eq!(
seen.len(),
CRATE_DEPS.len(),
"a CRATE_DEPS entry names no crate"
);
}
#[test]
fn the_production_part_ends_at_the_first_test_module() {
let text = "fn a() {}\n\
#[cfg(test)]\n\
fn helper() {}\n\
fn b() { db.raw_pool(); }\n\
#[cfg(test)]\n\
mod tests {\n\
fn c() { db.raw_pool(); }\n\
}\n";
let production = production_part(text);
assert_eq!(production.matches("raw_pool(").count(), 1, "{production}");
assert!(production.contains("fn b()"));
assert!(!production.contains("mod tests"));
for visibility in ["", "pub ", "pub(crate) ", "pub(super) "] {
let text = format!(
"fn b() {{ db.raw_pool(); }}\n#[cfg(test)]\n{visibility}mod tests {{\n\
fn c() {{ db.raw_pool(); }}\n}}\n"
);
let production = production_part(&text);
assert_eq!(
production.matches("raw_pool(").count(),
1,
"`{visibility}mod tests` did not end the production part"
);
}
assert_eq!(production_part("fn only() {}\n"), "fn only() {}\n");
assert!(is_test_file("crates/signer/src/relay/tests/lifecycle.rs"));
assert!(is_test_file("crates/core/src/audit/tests.rs"));
assert!(is_test_file("crates/store/src/testutil.rs"));
assert!(!is_test_file("crates/admin/src/admin/ops.rs"));
}